injections = PDO or Mysqli with bind values or params
XSS = make your GET value as int or sting ,htmlspecialchars(),sprintf(),int();
this is enough friends ?
still unable to see this mod bcz i never bought NWE game lic but i want little bit logic help so my is question following
question :-how can i check i ve already rated the current profile of player ?
you have run two queries, one for row update and one for delete row or you can just simply manually change id number from database
advice :-you should take back up before do this